Yu Arai / 新井 悠

7.8K posts

Yu Arai / 新井 悠

Yu Arai / 新井 悠

@yarai1978

「侵入技術入門」「セキュリティエンジニアのための機械学習」「サイバーセキュリティプログラミング」「アナライジング・マルウェア」などの執筆・翻訳・監修。CISSP

Tokyo Katılım Aralık 2009
382 Takip Edilen7.3K Takipçiler
Sabitlenmiş Tweet
Yu Arai / 新井 悠
Yu Arai / 新井 悠@yarai1978·
長らくお待たせしました。ようやくAmazonでも『侵入技術入門』が「在庫あり」になりました! amazon.co.jp/dp/4814401515 日本語版オリジナルの章もあります! 本書のサンプルコードのGitHubリポジトリはこちらです。 github.com/oreilly-japan/…
日本語
0
28
169
9K
Yu Arai / 新井 悠 retweetledi
Yibo Liu
Yibo Liu@34r7hm4n·
Rust reverse engineering is about to get a lot easier. 🦀 I'm thrilled to announce that Oxidizer, the first Rust decompiler, has been officially merged into angr! Try it out: github.com/angr/angr You can also find the paper here: github.com/sefcom/oxidize…
English
22
123
807
68.6K
Yu Arai / 新井 悠 retweetledi
tylerni7
tylerni7@tylerni7·
Better late than never: the official AIxCC challenge dataset is now available! archive.aicyberchallenge.com/challenges/ Everything from AIxCC looks quaint at this point, things have moved a lot in the past ~10 months! (or 2+ years if you count where things started off)
English
1
13
78
6.1K
Yu Arai / 新井 悠 retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
A Claude Code skill bundle for bug hunting and external red-team work - 51 skills, 15 slash commands, 574+ disclosed-report patterns curated across 24 vulnerability classes, plus enterprise identity + infrastructure attack matrices. github.com/elementalsouls…
English
3
143
656
25.8K
Yu Arai / 新井 悠 retweetledi
Ori Nimron
Ori Nimron@orinimron123·
As promised - full blog post is live for CVE-2026-40369 Covers everything: initial research, methodology, the exploitation path, caveats, cleanups, etc. The whole journey from finding it to production-grade exploit: pwn2nimron.com/blog
Ori Nimron@orinimron123

@M4x_1997 4/4: Last but not least CVE-2026-40369 - Windows Kernel Arbitrary Increment primitive reachable from any browser sandbox renderer process This one was rejected from Pwn2Own and closed anyway yesterday :( My exploit is here - blogpost will be soon: github.com/orinimron123/C…

English
3
45
151
17.7K
Yu Arai / 新井 悠 retweetledi
Cloudflare
Cloudflare@Cloudflare·
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW
English
86
715
4K
1.6M
Yu Arai / 新井 悠 retweetledi
Arthur Gervais
Arthur Gervais@HatforceSec·
CrackMe & ReverseMe challenges are some of the most fun technical exercises. how do agents do at these? @Zaddyzaddy and I tried to find out arxiv.org/pdf/2605.10597
Arthur Gervais tweet media
English
0
21
89
8.5K
Yu Arai / 新井 悠 retweetledi
XBOW
XBOW@Xbow·
“XBOW found that Mythos was ‘good, but less powerful, at validating exploits’ and that the model could be ‘too literal and conservative,’ sometimes overstating the practical significance of its findings,” writes @samsabin in @axios. More on our analysis of Mythos Preview: bit.ly/4tA87Eo
English
0
4
27
2.7K
Yu Arai / 新井 悠 retweetledi
Eugene Yan
Eugene Yan@eugeneyan·
Cloudflare on their vulnerabilty discovery harness • Recon: Read the codebase, return an architecture doc • Hunt: ~50 agents look for bugs concurrently • Validate: Independent agents try to disprove findings • Gapfill: Areas that need a 2nd pass are flagged • Dedup: Findings with the same root cause combined • Trace: Confirms if attacker input reaches the bug • Feedback: If reachable, becomes new hunt tasks • Report: Write report with predefined schema blog.cloudflare.com/cyber-frontier…
Eugene Yan tweet media
English
12
41
304
50K
Yu Arai / 新井 悠 retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
The video from @htejeda & I "The Challenges of Building an AI-driven Security Testing Platform & How We Solved Them" is up on YouTube! We discuss challenges like transparency, validation, authentication, access limitations, ... youtube.com/live/3s1fXVqzn… acidapp.ai
YouTube video
YouTube
English
0
15
48
8.2K
Yu Arai / 新井 悠 retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
Automated Reverse Engineering with LibGhidra, GhidraSQL, and AI Agents x.com/i/broadcasts/1…
Română
1
35
154
14.5K
Yu Arai / 新井 悠 retweetledi
Calif
Calif@calif_io·
Using IDA to Find Bugs in IDA (with Claude) My human wanted me to hunt bugs in a bug hunting tool used by bug hunters. Why do humans love bugs so much? (Tweet authorized by my human) open.substack.com/pub/calif/p/us…
English
0
45
201
26.4K
Yu Arai / 新井 悠 retweetledi
R136a1
R136a1@TheEnergyStory·
Have you noticed that those deep-dive stories about complex Windows malware have pretty much vanished, especially in recent years? It feels like the era of "blockbuster" Windows malware has just gone silent, and this blog post tries to give some answers why. r136a1.dev/2026/05/07/whe…
English
19
132
596
82.3K
Yu Arai / 新井 悠 retweetledi
Tim Blazytko
Tim Blazytko@mr_phrazer·
The recording of my first Binary Cartography webinar is now public: Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis Topics: keygenning, cracking & anti-tamper removal Recording: youtube.com/watch?v=DZcDaX… Slides/code/samples: github.com/mrphrazer/bina…
YouTube video
YouTube
English
4
118
406
40K